在 OpenStack Keystone 29.0.3 之前的版本中,通过委托认证机制(如 OAuth1 访问令牌、应用凭据、信任委托)获取的令牌,可以被提交到令牌方法认证路径以进行重新认证,从而绕过其预期的项目作用域限制。当提交的应用凭据令牌没有显式指定作用域时,Keystone 会颁发一个以该凭据所有者默认项目为作用域的新令牌,而不是该凭据被创建时所归属的项目,从而规避了预期的项目边界。所有支持通过 OAuth1 访问令牌、应用凭据或信任委托进行委托认证的 Keystone 部署均受此漏洞影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet